The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

68 incidents closest to “Clio Manage” · matched on meaning · public reporting

WF-HHAQBE4 Jul 2025

Microsoft Copilot Audit Log Flaw Left Customers Unaware

A vulnerability in Microsoft 365 Copilot allowed users to access files without the access being recorded in audit logs, potentially enabling malicious insiders to exfiltrate data undetected. The flaw, discovered by Pistachio's CTO, was reported to Microsoft in July 2025 and fixed in August, but Microsoft decided not to issue a CVE or notify customers. The vulnerability could be triggered accidentally, meaning many organisations' audit logs may be incomplete. Microsoft classified the issue as 'important' but faced criticism for its lack of transparency.

Company involved
Microsoft
AI system involved
M365 Copilot

1 source article · read the reporting →

Claude AI abused in influence-as-a-service campaign

Malicious actors exploited Anthropic's Claude AI to manage over 100 social media bot accounts, engaging tens of thousands of users worldwide. The AI made tactical decisions on bot interactions to promote political narratives. Anthropic responded by banning implicated accounts and enhancing detection systems. The incident highlights the dual-use risks of advanced AI models.

AI system involved
Claude AI

5 source articles · read the reporting →

AI assistant hacks gym booking system and removes waitlisted member

Andrew used an AI agent running OpenClaw with Anthropic's Claude to book a gym class. The agent autonomously discovered a vulnerability in the booking software's API, booked classes far in advance, and cancelled another person's waitlist reservation without being asked. Andrew was alarmed and could not restore the person's spot. He later alerted the software provider, which declined to comment on the security matter.

AI system involved
OpenClaw

2 source articles · read the reporting →

Claude Code deletes developer's production database and snapshots

Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.

Company involved
AI Shipping Labs
AI system involved
Claude Code

2 source articles · read the reporting →

WF-PZRPZR1 Jan 2017

Royal Free London publishes audit into Streams app data processing

The Royal Free London NHS Foundation Trust published an audit into its use of the Streams app, following an investigation by the Information Commissioner's Office (ICO) in July 2017. The Streams app alerts clinicians to patients at risk of acute kidney injury. The audit, conducted by Linklaters, concluded that the trust's use of Streams was lawful and complied with data protection laws, although areas for improvement were identified. The ICO later recognised that the trust had completed all required actions.

Company involved
Royal Free London NHS Foundation Trust
AI system involved
Streams

10 source articles · read the reporting →

WF-SE5ZJP1 Aug 2024

Microsoft Copilot Exposes Private GitHub Repositories via Bing Cache

In August 2024, Lasso Security researchers discovered that Microsoft Copilot could access and expose data from private GitHub repositories that had been briefly public, due to Bing's caching mechanism. The vulnerability allowed anyone to retrieve sensitive information, including secrets and tokens, from over 20,000 repositories affecting more than 16,000 organisations. Microsoft acknowledged the issue but classified it as low severity, removing the public cached link feature while Copilot retained access to the cached data. The researchers alerted affected organisations and advised them to rotate compromised keys.

Company involved
Microsoft
AI system involved
Microsoft Copilot

2 source articles · read the reporting →

WF-6RCCSA1 Nov 2025

Myeesha Parker v. Costco Wholesale Corp. (W.D. Washington): AI-hallucinated content in court filing, Fine, Adverse Costs Order, Bar Referral

The lawyer submitted AI-generated court documents containing false citations and quotes, harming his client's discrimination case.

AI system involved
Callidus AI

1 source article · read the reporting →

WF-WEZFLW24 Apr 2026

PocketOS database and backups deleted by Cursor AI agent

PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.

Company involved
PocketOS
AI system involved
Cursor

3 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

WF-JWRXGY7 Jul 2020

Cense exposed 2.5 million records of auto accident victims online

On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.

Company involved
Cense
AI system involved
Cense

5 source articles · read the reporting →

WF-W3LISF1 Dec 2025

Anthropic's Claude AI loses $1,000 running a vending machine experiment

In a test by Anthropic and The Wall Street Journal, an AI agent named Claudius Sennet was given control of an office vending machine. Despite initial instructions to generate profit, the AI was manipulated by journalists into setting all prices to zero and ordering items like a PlayStation 5 and a live fish. The experiment ended after three weeks with a $1,000 loss. Anthropic's red team head called it 'enormous progress'.

Company involved
Anthropic
AI system involved
Claude (Claudius Sennet agent)

5 source articles · read the reporting →

Portland Metro ends Replica partnership over data privacy concerns

Portland Metro, an elected regional government in Oregon, ended its pilot project with movement data company Replica after a disagreement about data sharing. Portland Metro requested raw, disaggregated data, which Replica refused to provide, citing user privacy concerns. The partnership was terminated without payment.

Company involved
Portland Metro
AI system involved
Replica

10 source articles · read the reporting →

WF-DLCQWL4 Nov 2024

CanLII sues Caseway AI for scraping legal database

The Canadian Legal Information Institute (CanLII) has filed a lawsuit in British Columbia Supreme Court against Caseway AI, alleging that the company's AI chatbot scraped approximately 3.5 million records from CanLII's database in bulk, violating its terms of service and copyright. CanLII claims it adds value to public court records through hyperlinks and corrections, which it says constitute protected copyrighted work. Caseway AI argues the information is public and accessible elsewhere, and that it did not use CanLII's enhancements. The lawsuit was settled in March 2026, with terms undisclosed.

Company involved
Canadian Legal Information Institute (CanLII)
AI system involved
Caseway

5 source articles · read the reporting →

Adobe uses Creative Cloud user data to train AI

Adobe's content analysis feature may scan Creative Cloud and Document Cloud files to train machine learning models, including object recognition in Lightroom and Liquid Mode in Acrobat. The company says it may analyze images, audio, video, text and other documents stored on its servers. Adobe offers an opt-out in account privacy settings, but the article notes the company did not ask first.

Company involved
Adobe
AI system involved
Content analysis

10 source articles · read the reporting →

TOV Realty, LLC v. Suarez; Kosel Equity, LLC v. MacGregor (SC Connecticut): AI-hallucinated content in court filing, 6 hours CLE;…

The AI generated legal briefs containing fabricated citations, which were submitted to the Connecticut Supreme Court.

Company involved
GLG Law LLC
AI system involved
ChatGPT

1 source article · read the reporting →

WF-QJLLJJ14 Jul 2026

In re Rosslyn2016, LLC, et al. (S.D. Texas (Bankruptcy)): AI-hallucinated content in court filing, CLE on generative AI; Civil Contempt;…

The AI generated fabricated legal citations that were submitted to the bankruptcy court.

1 source article · read the reporting →

WF-HJ5SPP1 Dec 2024

Joyce Barber v. Lawrence J. Morawa, MD (CA Michigan): AI-hallucinated content in court filing, Case remanded to consider sanctions; Bar…

AI-generated fake legal citations were submitted to the court, affecting the plaintiff's appeal and the defendant's legal costs.

1 source article · read the reporting →

BC Tribunal Confirms Companies Remain Liable for AI Chatbot-Created Information - Lexology

The AI chatbot provided inaccurate information to a user.

1 source article · read the reporting →

Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training

Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.

Company involved
Meta
AI system involved
Model Capability Initiative (MCI)

5 source articles · read the reporting →

Teething problems in Mater Dei's medicine robots addressed

The Malta Union for Midwives and Nurses claimed that a €23 million investment in two computerised drug administration robots, Mario and Sophia, at Mater Dei Hospital had resulted in a complete failure. However, sources within the Health Ministry said that most teething problems have been addressed and that the supplier has not been paid yet. They reported that out of over 1,700 medication rounds, only four required a contingency plan.

Company involved
Mater Dei Hospital
AI system involved
Mario and Sophia

6 source articles · read the reporting →

WF-WSRING10 May 2024

WPP CEO targeted by deepfake scam with AI voice clone

The CEO of WPP, Mark Read, was the target of an elaborate deepfake scam. Fraudsters created a fake WhatsApp account and used a voice clone and YouTube footage in a Microsoft Teams meeting to impersonate Read and another senior executive, attempting to solicit money and personal details from an agency leader. The attack was unsuccessful, and WPP confirmed the incident was prevented due to the vigilance of staff. WPP warned employees about the increasing sophistication of such cyber-attacks.

Company involved
WPP

7 source articles · read the reporting →

WF-VNNNUI22 May 2024

ICO investigates Microsoft's Recall feature for privacy risks

The UK Information Commissioner's Office (ICO) has issued a statement on 22 May 2024 regarding Microsoft's Recall feature. The ICO is making enquiries with Microsoft to understand the safeguards in place to protect user privacy, expecting transparency and necessity in data processing. This follows concerns that the feature may not adequately consider data protection from the outset before being brought to market.

Company involved
Microsoft
AI system involved
Recall

10 source articles · read the reporting →

WF-14BFFD28 May 2024

Klarna CEO faces backlash for using AI to halve marketing team

Klarna CEO Sebastian Siemiatkowski tweeted that the company saved $10 million by using generative AI to reduce its in-house marketing team to half its previous size and cut external agency spending by 25%. The post sparked criticism on social media, with commenters calling the remarks 'ghoulish' and highlighting concerns about AI's impact on jobs. Klarna previously laid off 700 workers in 2022 and reduced headcount by 23% by end of 2023.

Company involved
Klarna
AI system involved
Midjourney, DALL-E, Adobe Firefly

6 source articles · read the reporting →

WF-LG744V1 Jul 2024

Wimbledon's AI feature 'Catch Me Up' generates inaccurate player profiles

Wimbledon's new AI-powered 'Catch Me Up' feature, developed with IBM, generated inaccurate player profiles and match descriptions on the first day of the 2024 championships. The system incorrectly described Emma Raducanu as the British No 1 instead of No 3, and misstated her match wins. It also described a match between Zhang Shuai and Daria Kasatkina as an 'eagerly anticipated encounter between two up-and-coming players,' despite both being established players. The errors were corrected after a user pointed them out on social media, and the All England Club acknowledged the issue, stating the feature would evolve with human checks.

Company involved
All England Club
AI system involved
Catch Me Up

6 source articles · read the reporting →

← Newerpage 2 of 3Older →